CVEs classified under CWE-173, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (4)
CVE-2026-10050 — CVSS 9.1 (critical): In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because…
CVE-2026-19611 — CVSS 7.4 (high): A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth…
CVE-2023-26303 — CVSS 3.3 (low): Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially…
CVE-2023-26302 — CVSS 3.3 (low): Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid…